● DoD Compliance · Cyber Workforce

DoD 8570 Has Been Gone Since 2023. Most Job Postings Still Ask for It

Travis D. Butera September 3, 2026 6 min read

Open any cleared cybersecurity job posting this week and there is a good chance it asks for a certification "per DoD 8570" or names an "IAT Level II baseline." I have seen it in postings written this year, in contract statements of work, and in the certification table on my own website until I corrected it while writing this.

DoD 8570 has not been the governing policy since 15 February 2023. It was superseded on the release of DoD Manual 8140.03, the Cyberspace Workforce Qualification and Management Program (DoD Cyber Exchange transition paper, retrieved 3 September 2026). That is more than three years of a retired framework being cited as a current requirement.

This is not pedantry about a document number. The replacement changed the substance of how people qualify, and the change works in favor of experienced practitioners in a way that almost nobody is taking advantage of.

The part everyone gets wrong

Under the old model, the mental shortcut was simple and mostly accurate: find your category and level, hold one of the listed certifications, and you are compliant. A cert was the ticket. That shortcut is why the entire defense hiring market still thinks in terms of "do you have Security+."

DoDM 8140.03 does not work that way. Qualification is now tied to a specific work role in the DoD Cyber Workforce Framework, and the foundational portion offers three options, not one. Per the manual, personnel must "complete any one of the three foundational qualification options":

Education. A secondary diploma at minimum, with higher education evaluated against the work role.

Training. Coursework that covers 70 percent of the core task and knowledge, skills and abilities content for that role.

Personnel certification. A certification accredited to ISO/IEC 17024.

Any one of the three satisfies the foundational requirement. A certification is a path, not the path. I have watched capable people conclude they were locked out of a role because they did not hold a specific four-letter credential, when the education or training path was open to them the whole time.

Foundational is only half of it

The second half is the piece that has no equivalent in the old framework, and it is the one hiring managers should care about most. Alongside the foundational area, 8140.03 requires residential qualification: a formal period of supervised engagement covering the task and knowledge, skills and abilities content for the role before the individual works unsupervised.

Read that again with an operational eye. The policy now says out loud that holding a certificate does not mean you can do the job, and it builds a supervised on-the-job period into the qualification itself. Anyone who has watched a freshly certified technician meet a live accreditation boundary for the first time understands exactly why that clause exists.

There is also continuous professional development on top of both, which is the part that most resembles the old continuing-education cycle.

The two clocks

The manual attaches deadlines to assignment, not to hiring or to fiscal year:

Missing either one requires removal from the role unless a waiver is granted. That is a materially different posture from the old one, where a lapse tended to surface as an administrative finding during an inspection and then sat in a tracker.

I have some personal history with exactly that failure mode. My own Security+ lapsed in 2018 and nothing in the system caught it for years, which I wrote about honestly rather than quietly fixing. Under a clock tied to assignment with removal as the consequence, that gap is visible far sooner. This is an improvement, and I say that as someone it would have caught.

If you are writing the job posting

Three things are worth correcting, and none of them cost anything:

If you are the candidate

The practical read is less dramatic than it sounds. Certifications remain the cleanest, most portable evidence, because they travel between employers and clear automated filters that were built during the 8570 era and never updated. A recruiter's applicant tracking system does not read DoD manuals.

So the honest advice is to hold the certification anyway, while knowing three things the average applicant does not:

That last point is the one I would emphasize if you are transitioning. The framework moved toward what you actually did, and away from what you can produce a PDF for.

What I changed on this site

Writing this cost me a correction. My own certification tracker cited the "DoD 8570 Baseline" next to Security+, which is the exact error I am describing. I fixed it the same day. A current Information System Security Manager citing a framework retired three years ago is not a good look, and I would rather find it myself than have a hiring manager find it for me.

The one thing I would not do is treat the qualification matrix as settled. The certification-to-role mappings and proficiency tiers are maintained separately from the manual and are revised on their own schedule, and the authoritative view for a specific role sits behind DoD access. If you need the answer for a particular billet, confirm it through your command or DoD COOL rather than through any article, including this one.

If you are transitioning out of a cleared role and trying to work out which credentials actually matter for where you are going, that is a conversation worth having and I am happy to have it. Reach me at travis@buteranet.com.

Travis D. Butera

TB
Travis D. Butera
U.S. Navy Senior Chief & ISSM with 18+ years executing DoD cybersecurity, RMF/ATO lifecycles, and enterprise IT programs across seven operational submarines. NEC 741A (ISSM), NEC 742A (NSVT). Active TS/SCI. Available February 2028.

travis@buteranet.com  ·  buteranet.com